Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 6.8 CVE-2014-2066 Session fixation vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to hijack web sessions via vectors involving th… Jenkins after 1.550 Fix from $1,6002014-10-17 HIGH 9.3 CVE-2014-2927EPSS 8% The rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before HF7, 11.3.0 before HF9, and … Arx No fix yet Fix from $1,9502014-10-15 HIGH 7.5 CVE-2014-6379 Juniper Junos 11.4 before R12, 12.1 before R10, 12.1X44 before D35, 12.1X45 before D25, 12.1X46 before D20, 12.1X47 before D10, 12.2 before R8, 12.2X… Junos Mitigation only Fix from $1,9502014-10-14 MEDIUM 5.0 CVE-2014-3402 The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7.0(8)E4 and earlier in Cisco Intrusion Detection … Intrusion Prevention System after 7.0 Fix from $1,6002014-10-10 HIGH 7.5 CVE-2014-6632 Joomla! 2.5.x before 2.5.25, 3.x before 3.2.4, and 3.3.x before 3.3.4 allows remote attackers to authenticate and bypass intended access restrictions… Joomla\! Mitigation only Fix from $1,9502014-10-08 MEDIUM 5.0 CVE-2014-5300EPSS 7% Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0 allows remote attackers to bypass the signature check, impersonate arbitrary users, and execu… Moab after 7.2.8 Fix from $1,6002014-10-08 HIGH 7.5 CVE-2014-0074EPSS 5% Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an e… Shiro No fix yet Fix from $1,9502014-10-06 HIGH 8.3 CVE-2013-3092 The Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication and gain privileges via vectors related to incorrect validation o… N300 Firmware No fix yet Fix from $1,9502014-09-29 MEDIUM 5.0 CVE-2014-3106 IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 does not properly implement the Local Access Only protec… Rational Clearcase Patch available Fix from $1,6002014-09-23 MEDIUM 5.0 CVE-2014-3101 The login form in the Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 does not insert a… Rational Clearcase Patch available Fix from $1,6002014-09-23 MEDIUM 5.0 CVE-2014-5412 Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote attackers to read database records by leveraging access… Clearscada Mitigation only Fix from $1,6002014-09-18 HIGH 7.5 CVE-2014-2685 The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 v… Zend Framework after 2.0.1 Fix from $1,9502014-09-04 HIGH 9.3 CVE-2014-4619 EMC RSA Identity Management and Governance (IMG) 6.5.x before 6.5.1 P11, 6.5.2 before P02HF01, and 6.8.x before 6.8.1 P07, when Novell Identity Manag… Rsa Identity Management And Governance No fix yet Fix from $1,9502014-08-28 MEDIUM 6.0 CVE-2014-0482 The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release c… Django after 1.4.13 Fix from $1,6002014-08-26 HIGH 7.2 CVE-2014-4325 The cmd_boot function in app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contri… Little Kernel Bootloader Patch available Fix from $1,9502014-08-25 HIGH 7.2 CVE-2014-0973 The image_verify function in platform/msm_shared/image_verify.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center … Little Kernel Bootloader Patch available Fix from $1,9502014-08-25 MEDIUM 5.0 CVE-2014-5385 com/salesmanager/central/profile/ProfileAction.java in Shopizer 1.1.5 and earlier does not restrict the number of authentication attempts, which make… Shopizer after 1.1.5 Fix from $1,6002014-08-21 HIGH 7.5 CVE-2014-5175 The License Measurement servlet in SAP Solution Manager 7.1 allows remote attackers to bypass authentication via unspecified vectors, related to a ve… Solution Manager Mitigation only Fix from $1,9502014-07-31 MEDIUM 6.4 CVE-2014-3895 The I-O DATA TS-WLCAM camera with firmware 1.06 and earlier, TS-WLCAM/V camera with firmware 1.06 and earlier, TS-WPTCAM camera with firmware 1.08 an… Ts Wlcam\/v Camera Firmware after 1.08 Fix from $1,6002014-07-29 MEDIUM 6.0 CVE-2014-3552 The Shibboleth authentication plugin in auth/shibboleth/index.php in Moodle through 2.3.11, 2.4.x before 2.4.11, and 2.5.x before 2.5.7 does not chec… Moodle after 2.3.11 Fix from $1,6002014-07-29 HIGH 7.5 CVE-2014-4725EPSS 60% The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrar… Mailpoet Newsletters after 2.6.6 Fix from $1,9502014-07-27 HIGH 10.0 CVE-2014-2955 Raritan PX before 1.5.11 on DPXR20A-16 devices allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher s… Px after 1.5.8 Fix from $1,9502014-07-14 HIGH 7.5 CVE-2013-6117EPSS 70% Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials,… Dvr Firmware No fix yet Fix from $1,9502014-07-11 MEDIUM 6.9 CVE-2014-3312 The debug console interface on Cisco Small Business SPA300 and SPA500 phones does not properly perform authentication, which allows local users to ex… Spa 301 1 Line Ip Phone Mitigation only Fix from $1,6002014-07-09 HIGH 7.5 CVE-2014-2614 Unspecified vulnerability in HP SiteScope 11.1x through 11.13 and 11.2x through 11.24 allows remote attackers to bypass authentication via unknown ve… Sitescope Mitigation only Fix from $1,9502014-07-07 MEDIUM 5.0 CVE-2014-4168 (1) iodined.c and (2) user.c in iodine before 0.7.0 allows remote attackers to bypass authentication by continuing execution after an error has been … Iodine after 0.6.0 Fix from $1,6002014-07-03 MEDIUM 6.8 CVE-2014-4668 The cherokee_validator_ldap_check function in validator_ldap.c in Cherokee 1.2.103 and earlier, when LDAP is used, does not properly consider unauthe… Fedora after 1.2.103 Fix from $1,6002014-07-02 MEDIUM 6.8 CVE-2014-2005 Sophos Disk Encryption (SDE) 5.x in Sophos Enterprise Console (SEC) 5.x before 5.2.2 does not enforce intended authentication requirements for a resu… Enterprise Console after 5.2.1 Fix from $1,6002014-06-25 HIGH 8.0 CVE-2014-3053 The Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Acce… Security Access Manager For Web 8.0 Firmware Mitigation only Fix from $1,9502014-06-21 HIGH 10.0 CVE-2014-2609EPSS 13% The Java Glassfish Admin Console in HP Executive Scorecard 9.40 and 9.41 does not require authentication, which allows remote attackers to execute ar… Executive Scorecard Mitigation only Fix from $1,9502014-06-19